目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2019-11510 PoC — Pulse Secure Pulse Connect Secure 路径遍历漏洞

来源
关联漏洞
标题: Pulse Secure Pulse Connect Secure 路径遍历漏洞 (CVE-2019-11510)
Description:Pulse Secure Pulse Connect Secure(又名PCS,前称Juniper Junos Pulse)是美国Pulse Secure公司的一套SSL VPN解决方案。 Pulse Secure PCS 9.0RX版本、8.3RX版本和8.2RX版本中存在路径遍历漏洞。该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素。攻击者可利用该漏洞访问受限目录之外的位置。
Description
cve-2019-11510, cve-2019-19781, cve-2020-5902,                cve-2021-1497, cve-2021-20090,  cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
介绍
# APT-Backpack
Most common used CVE's by APT, legitimate RAT and other tools used by adversary

## CVE's

- CVE-2019-11510 (Pulse Connect Secure 8.2 8.3 9.0)          **Unauth file read**          
- CVE-2019-19781 (Citrix ADC & Gateway)                      **Directory Traversal**
- CVE-2020-5902  (F5 Big IP)                                 **RCE**
- CVE-2021-1497  (Cisco HyperFlex HX)                        **Unauth Command injection**
- CVE-2021-20090 (Buffalo WSR-2533DHP2 WSR-2533DHP3)         **Unauth RCE**
- CVE-2021-22006 (Vmware vCenter Server)                     **Authentication bypass**
- CVE-2021-22205 (GitLab CE/EE)                              **RCE**
- CVE-2021-26084 (Atlassian Confluence)                      **Unauth RCE**
- CVE-2021-26855 (Microsoft Exchange Server)                 **RCE**
- CVE-2021-26857 (Microsoft Exchange Server)                 **RCE**
- CVE-2021-26858 (Microsoft Exchange Server)                 **RCE**
- CVE-2021-26865 (Microsoft Exchange Server)                 **RCE**
- CVE-2021-36260 (Hikvision)                                 **Command Injection**
- CVE-2021-40539 (ManageEngine ADSelfService Plus)           **API Auth bypass** -> **RCE** 
- CVE-2021-41773 (Apache HTTP Server 2.4.49)                 **Path Traversal**
- CVE-2021-42237 (Sitecore XP 7.5)                           **Deserialisation** -> **RCE**
- CVE-2021-44228 (Apache Log4j)                              **RCE**
- CVE-2021-40444 (Microsoft Office)                          **RCE**
- CVE-2022-1388  (F5 BIG-IP)                                 **RCE**
- CVE-2022-24112 (Apache APISIX 2.12.1)                      **RCE**
- CVE-2022-26134 (Atlassian Confluence)                      **RCE**

## Legitimate RAT (Remote Administration Tools) & Servers sockets

- Ammyy admin client v3 (windows) (This is caught by many defenses)
- Ngrok client (windows/linux)

## Exploitation 

- Sysinternals suite
- PSTools

## Exfiltration

- XXD static (windows)

## Phishing

- Office document with warnings (enable content)

## Reverse shell

- Ncat OPENBSD

*Use it rightly, i'm not resposible about any bad use of this pack*
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →